October 2, 2026
How to find valid bug using Shodan + Nuclei Step by Step guide | by Samadhan Shimple
Shodan for reconnaissance and Nuclei for detection. Hereβs how it works, and why itβs become a staple in modern bug bounty hunting.

By Samadhan shimple
3 min read
π The Setup: Why Shodan + Nuclei?
The internet is a massive, constantly shifting attack surface. Manually checking every IP or domain for a specific vulnerability is impossible. Shodan acts as a passive search engine for internet-connected devices, letting you filter by software, headers, and banners. Nuclei is a fast, template-based vulnerability scanner that sends targeted requests to confirm if a vulnerability actually exists.
The synergy is simple: Shodan narrows the haystack; Nuclei finds the needle. Shodan can identify thousands of potentially vulnerable services in seconds, but its banner-based detection can be noisy. Nuclei then actively probes those candidates with precise payloads to eliminate false positives and confirm real vulnerabilities.
Video Tutorial : https://youtu.be/NcgAHgcuNVQ?si=QUX8IamAtjfHk7sm
Tool Installation:
Install the required tools before starting:
# Install Shodan CLI (Python)
pip install shodan
# Initialize Shodan with your API key (free tier: 100 queries/month)
shodan init YOUR_API_KEY
# Install Nuclei (requires Go 1.21+)
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
# Update Nuclei templates (11,000+ community templates)
nuclei -update-templates# Install Shodan CLI (Python)
pip install shodan
# Initialize Shodan with your API key (free tier: 100 queries/month)
shodan init YOUR_API_KEY
# Install Nuclei (requires Go 1.21+)
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
# Update Nuclei templates (11,000+ community templates)
nuclei -update-templatesπ― The Hunt: A Real-World Walkthrough:
Step 1: Choose Your Target CVE:
Select a CVE from the Nuclei templates, extract its corresponding Shodan query, and then execute that query within the Shodan search engine.
Step 2: Shodan Reconnaissance:
Use Selected query in shodan then you will get there information about IP and services.
product:"Grafana"product:"Grafana"Then Go on ip address and use there following script in CONSOLE
var ipElements = document.querySelectorAll("strong");
var ips = [ ];
ipElements.forEach(function (e){
ips.push(e.innerHTML.replace(/[""]/g, ""));
});
var ipsString = ips.join("\n");
var a = document.createElement("a");
a.href = "data:text/plain;charset=utf-8," + encodeURIComponent(ipsString);
a.download = "ips.txt";
document.body.appendChild(a);
a.click();var ipElements = document.querySelectorAll("strong");
var ips = [ ];
ipElements.forEach(function (e){
ips.push(e.innerHTML.replace(/[""]/g, ""));
});
var ipsString = ips.join("\n");
var a = document.createElement("a");
a.href = "data:text/plain;charset=utf-8," + encodeURIComponent(ipsString);
a.download = "ips.txt";
document.body.appendChild(a);
a.click();
Step 3: Nuclei Vulnerability Scanning :
Use there following command with nuclei template
cat ip.txt | nuclei -t nuclei-templates/http/cves/2025/CVE-2025-4123.yamlcat ip.txt | nuclei -t nuclei-templates/http/cves/2025/CVE-2025-4123.yamlThen You can Observe there.
Why Nuclei?
- Deterministic templates: Each template is designed for a specific CVE with logic to reduce false positives.
- Speed and scale: It can scan thousands of hosts in minutes.
- Reproducibility: The same template can be run repeatedly to validate findings.
Validation and Results
From the scanned domains, one production application returned a positive match. The response behavior aligned precisely with the expected fingerprint. Before reporting, I performed a safe manual validation confirming the request/response cycle and execution context without running any destructive commands or accessing data.
This step is crucial. Automated tools can produce false positives, and a bug bounty report is only as good as its validation.
βοΈ The Reality Check: Shodan vs. Nuclei Accuracy
It's important to understand the strengths and weaknesses of each tool. A large-scale study analyzing 37 CVEs across 104,930 endpoints found:
- For banner-based detection (Shodan's default method), Nuclei contradicted over 95% of Shodan's detections for 18 out of 21 CVEs, suggesting banner-based results are often false positives.
- For payload-based detection (active probing), Nuclei found 2 to 36 times more vulnerable endpoints than Shodan for 10 CVEs, indicating Shodan may suffer from significant false negatives.
The takeaway: Use Shodan for broad reconnaissance and candidate discovery, but always rely on Nuclei to confirm whether a vulnerability is real.
Ethical and Operational Best Practices
- Rate limiting is your friend. When scanning government or large-scale domains, use flags like
-rl 10(rate limit) and-bs 2(bulk size) to avoid overwhelming targets and tripping firewalls. - Focus on severity. Filter Nuclei results with
-s critical,high,mediumto prioritize the bugs that matter. - Responsible disclosure. Once you confirm a vulnerability, report it through the proper channels. Never exploit it beyond proof-of-concept.
- Automate, but verify. Tools like Nuclei can run while you sleep, but always manually validate findings before submission.
π Final Thoughts
Finding bugs with Shodan and Nuclei is less about luck and more about building a repeatable, efficient workflow. Shodan gives you the map; Nuclei gives you the metal detector. Together, they transform a vast, noisy internet into a focused list of actionable targets.
The next time a critical CVE drops, don't panic. Fire up Shodan, build your target list, and let Nuclei do the heavy lifting. Then β if you've configured it right you can grab a coffee, or even a nap, and wake up to real results.
Have questions or want to share your own recon workflow? Drop a comment below or connect with me on https://www.linkedin.com/in/samadhan-shimple/